Identity
Your biggest access risk may be the path no one sees.
Approved permissions can quietly connect into hidden access paths, creating identity risks no one intended.
When approved access becomes an unintended risk
Nobody approves an attack path. We approve a password-reset delegation here, a temporary administrator role there, and a cloud synchronization rule somewhere else. Each decision has a business reason. Put together, those decisions can create a route to a system nobody intended to expose.
That distinction matters. Most security programs evaluate access one entitlement at a time. Attackers evaluate access as a chain. If we only ask whether each permission is legitimate, we can miss the more important question: what becomes possible when those permissions are combined?
It starts with an account that passes every check
Consider a service desk technician. The account has MFA, passed its last access review and is not labeled privileged. The technician can reset passwords because that is part of the job. Years ago, however, the delegation was scoped more broadly than intended. If an attacker compromises that account, they may not become an administrator immediately—but they may gain the ability to become somebody with more access.
From there, a forgotten deployment group can provide local administrator rights across thousands of workstations. A database administrator signs in to one of those machines to solve an urgent problem. Their credentials or tokens become the next step. A hybrid identity configuration then connects an on-premises group to a powerful cloud role. Four reasonable configurations have now become one dangerous route. Nothing in that sequence has to be broken. The permissions are working exactly as configured. That is why these paths are so difficult to catch with controls designed to find malware, missing patches or obviously privileged accounts.
Nothing in that sequence has to be broken. The permissions are working exactly as configured. That is why these paths are so difficult to catch with controls designed to find malware, missing patches or obviously privileged accounts.
Access outlives the reason it was granted
Every environment has an attic: migration groups, contractor accounts, service principals and exceptions created to get a project over the line. The project closes, the team moves on and the access remains. It is rarely malicious. It is simply ownerless.
This is where I believe security teams should be more skeptical of the phrase “temporary access.” Temporary is not a description; it is an expiration mechanism. If access is not revoked automatically or does not trigger a timely review, it is standing access with optimistic labeling.
Then a deadline meets a policy
Those four thousand machines matter because of who signs in to them. Last Tuesday, a database administrator connected to a user’s desktop to troubleshoot a report that wouldn’t run. Ten minutes later, the problem was solved and everyone moved on.
The organization’s tiering policy says privileged accounts should never touch general-purpose endpoints—and that policy is correct. But policies eventually meet real-world deadlines. Depending on the authentication method and endpoint controls in place, credential material or session artifacts may remain after the administrator disconnects. In this case, the attacker already controls the workstation.
Where on-premises quietly becomes cloud
The database administrator is not a domain administrator. But her account belongs to a group with broad rights over part of the directory. That directory is synchronized with the cloud tenant, where the same group carries a global administrative entitlement—a connection established during a hybrid identity project by an engineer who left the organization two years ago.
Four moves: service desk to workstation fleet, workstation to directory, and directory to cloud tenant. No zero-day. No malware. No control was technically broken, because the permissions worked exactly as they were configured to work. They simply operated in a sequence no one intended.
The path had existed for years. The problem was that no one had ever mapped it.
Every identity has value. The question is to whom
Employees, contractors, service accounts, applications and cloud resources all represent trusted access to business-critical systems. As organizations adopt more cloud services, automation and AI, the number of identities keeps growing and so does the number of ways they connect. The scenario above needed four steps. Most environments offer far more, and the ones that matter are rarely on a privileged access list.
Rather than exploiting software vulnerabilities, today’s threats often target legitimate identities with existing access, which lets them move through an environment undetected. Identity risk isn’t always visible, which is precisely why it accumulates.
600M+
cybercriminal and nation-state attacks every day, including identity-based attacks that target users, credentials and access pathways.
Source: Microsoft 2024 Digital Defense Report
Why your existing investments missed it
When attackers take control of an identity, they inherit the trust already attached to that account. That allows them to operate via legitimate access and avoid many of the controls designed to detect external threats. The uncomfortable part is not simply that the path existed. It’s that the organization could have a mature security program in place and still not see it.
- Vulnerability management scanned every system in the chain and found nothing because there was no software vulnerability to find. The systems were patched. The path was built from permissions, and permissions do not have CVEs.
- Identity governance reviewed and certified every access grant involved. But access reviews typically evaluate entitlements one at a time. A manager may see a group name without seeing everything that group can reach through nested permissions and trust relationships.
- Privileged access management protected the accounts the organization had classified as privileged. The database administrator’s account was not included because privilege had been defined by role or account type—not by what the identity could ultimately reach.
- Multi-factor authentication was enforced and did its job by making the initial compromise more difficult. But MFA alone could not prevent the attacker from misusing an established session, compromised credentials or legitimate directory permissions after gaining access.
Each control answered an important question. None answered the question that ultimately determines the potential impact of a compromised identity: What can this account reach, and what path would an attacker use to get there?
The number that belongs on your board slide
Attack paths tend to converge. An enterprise may have thousands of theoretical routes to critical systems, but many of those routes depend on the same small set of relationships: a nested group, an overly broad delegation or a forgotten synchronization rule. These are the choke points where remediation can have the greatest effect. Removing one isolated permission may close one path. Correcting a shared choke point can eliminate many of them at once.
That changes identity risk from an endless cleanup exercise into a prioritization problem. Instead of asking how the organization will remediate every excessive permission—an effort few teams have the time or resources to complete—the question becomes: Which changes will eliminate the greatest number of paths to our most critical systems?
That is a question leadership can act on. It gives the work an owner, a timeline and a measurable outcome—and it focuses available resources where they will reduce risk the most.
It’s time to ask the real questions
“Who has access?” remains an important governance question, but it is no longer enough. I want teams to ask: “If this identity is compromised, what can it reach, and by what route?”
Answering that requires a graph of relationships—not another flat inventory. SpecterOps helps reveal how identities, permissions and trust relationships connect to critical systems. ConRes brings the assessment, architecture and engineering work required to turn that visibility into durable remediation, stronger least privilege and a more credible Zero Trust program.
Attackers have already run this analysis on environments like yours. The only real question is whether you see the paths first.
Curious what an attacker could reach from a single account in your environment? Schedule an identity assessment and see the paths before they do.
